CVE Database
/

CVE-2000-1218

Back to search

CVE-2000-1218

Published: Apr 21, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.

VendorProductVersions

n/a

n/a

affected
n/a

References

win2k-dns-resolver(4280)
vdb-entry
x_refsource_XF
VU#458659
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now